How To Make A Mint: The Cryptography Of Anonymous Electronic Cash (1996)
cryptome.org
cryptome.org
Then, in 1996(ish) I went to a talk by Simson Garfinkel, and asked him about e-cash. This dashed my hopes for e-cash. He specifically raised an important objection to all the e-cash schemes of the time: the "risk" of the system was essentially essentially infinite. An e-cash mint could, if subverted by hook or crook, print an infinite amount of e-cash, thus disrupting the entire system. (Imagine terrorists with guns going into an e-cash mint and saying "Print us one quadrillion dollars of money". In the e-cash systems of the time, a few minutes later, they would say "here ya gone, one quadrillion dollars of untraceable unrevokable money".)
I think the genius of the bitcoin system is that there is no central mint, and the "proof-of-work" system eliminates the possibility of someone minting an infinite amount of cash.
P.S. It's Saturday night and I'm not entirely sober. If you want to call me an idiot based on the above, well, that seems fair. On the other hand, if you want to argue with either Chaum or Garfinkel, please research and read what they actually wrote rather than rely on my drunken recollection.
When signing a coin to make a withdrawal, the bank is given
(r^v · M (mod N)) - N and v is publicly known, M and r are only known to Alice.
The bank computes r · M^s (mod N) (using s, which only the bank knows).Later, Bob supplies the bank with M', a message, and (r · M^s (mod N)) / r, and the bank is not supposed to be able to link M' back to M.
But the bank can enumerate all (r_i^v · M_i (mod N)) that it signed, and divide by M'; if M=M', the result is of the form r_i^v (mod N). The bank knows the prime factorisation N = pq, so they can test r_i^v (mod p) and r_i^v (mod q); for a prime modulus, computing a power residue is efficient, and for a large enough p and q (as you want in cryptography) and a moderately high v, this gives a high level of confidence that M=M'.
http://www1.icsi.berkeley.edu/~luby/PAPERS/blind.ps
> Without a trusted certification authority and a secure infrastructure, the above four security features cannot be achieved, and electronic commerce becomes impossible over an untrusted transmission medium.
The plus side of such a system is honest bank customers still get complete anonymity, even if the banks conspire against you. The downside is you can never know if your bank is conspiring against their customers as a whole i.e. by not operating in line with their inflation/reserve policy... which of course is one of Bitcoins best features.
2. What they are describing has a security definition and can be proved secure. Bitcoin has no security definition, no proof of security, and is vulnerable to polynomial time attacks.
Cite?
http://bitcoin.org/bitcoin.pdf
It is also described here:
https://en.bitcoin.it/wiki/Weaknesses#Attacker_has_a_lot_of_...
And in this criticism by Ben Laurie:
I am not sure what you mean. What do you think this is an attack against?
"you can't use a polynomial-time algorithm to spend coins which belong to me."
In some situations I can. If, for example, you received your money from me, I can take the money from you and transfer it to someone else. The attacker can also stop you from completing transactions and stop you from receiving rewards for mining.
https://www.google.com/#sclient=psy-ab&q="Tatsuaki+Okamoto"+...
http://academic.research.microsoft.com/Author/1002804/tatsua...
http://www.informatik.uni-trier.de/%7Eley/pers/hd/o/Okamoto:...